170
Nart Villeneuve and Masashi Crete-Nishihata
while it is possible that states may be instigating attacks, they cannot control outside
participants from contributing to them, and such contributions can lead to unpredictable outcomes.
59
Although we did not fi nd evidence of state attribution in our investigation, it does
not rule out the possibility that the SPDC is somehow involved in the recurring attacks
against Burmese opposition groups. However, their involvement may be more subtle
and indirect than speculations of elite military units leading cyber attacks on dissident
Web sites convey. It is possible that the SPDC is engaged with individuals and groups
in the Burmese hacker community and either subtly encourages them to participate
in attacks against opposition groups or at least condones their actions. Statesanctioned patriotic hackers have been suspected in other cyber attacks originating
from Russia, China, and Vietnam, but direct evidence is elusive.
60 The state may also
be employing third-party actors to conduct cyber attacks through a crime-as-a-service
model in which they hire criminal groups to perpetrate the attacks or rent necessary
resources such as botnets from them.
The use of technical infrastructure related to criminal activities in seemingly politically motivated cyber attacks has been observed in high-profi le cases such as attacks
on Georgian government Web sites during the 2008 Russia-Georgia confl ict.
61 This
model of privateering is potentially attractive to nation-states because it permits them
plausible deniability: actions take place in a criminal ecosystem that is removed from
state entities and diffi cult — if not impossible — to trace back to them. Confi rming these
speculative scenarios in Burma is diffi cult, since much remains unknown about the
attacks, the possible actors, and the motivations behind them. However, situating
these events within the wider context of recent cyber attacks in other countries shows
they are part of a troubling global trend that needs to be analyzed across both the
technical and political complexities of cyberspace.
62
Conclusion
Unlike Internet fi ltering at the ISP level that is limited to local control, cyber attacks
conducted at strategically sensitive times have the ability to disrupt information fl ows
to international audiences right when the content may have the most impact. States
are obvious units of analysis when examining attribution and intent behind national
fi ltering regimes. However, actors and their intentions are not as readily apparent in
politically motivated cyber attacks. Despite the diffi culties, due to the political nature
of attacks against civil society organizations, many observers attribute these incidents
to government and military entities. As a result, the attackers ’ capabilities are often
overestimated, and their motivations are unknown. Although the issue of attribution
is essential to analysis of such attacks, it remains the most diffi cult and ambiguous
component of any investigation.
Nart Villeneuve and Masashi Crete-Nishihata
while it is possible that states may be instigating attacks, they cannot control outside
participants from contributing to them, and such contributions can lead to unpredictable outcomes.
59
Although we did not fi nd evidence of state attribution in our investigation, it does
not rule out the possibility that the SPDC is somehow involved in the recurring attacks
against Burmese opposition groups. However, their involvement may be more subtle
and indirect than speculations of elite military units leading cyber attacks on dissident
Web sites convey. It is possible that the SPDC is engaged with individuals and groups
in the Burmese hacker community and either subtly encourages them to participate
in attacks against opposition groups or at least condones their actions. Statesanctioned patriotic hackers have been suspected in other cyber attacks originating
from Russia, China, and Vietnam, but direct evidence is elusive.
60 The state may also
be employing third-party actors to conduct cyber attacks through a crime-as-a-service
model in which they hire criminal groups to perpetrate the attacks or rent necessary
resources such as botnets from them.
The use of technical infrastructure related to criminal activities in seemingly politically motivated cyber attacks has been observed in high-profi le cases such as attacks
on Georgian government Web sites during the 2008 Russia-Georgia confl ict.
61 This
model of privateering is potentially attractive to nation-states because it permits them
plausible deniability: actions take place in a criminal ecosystem that is removed from
state entities and diffi cult — if not impossible — to trace back to them. Confi rming these
speculative scenarios in Burma is diffi cult, since much remains unknown about the
attacks, the possible actors, and the motivations behind them. However, situating
these events within the wider context of recent cyber attacks in other countries shows
they are part of a troubling global trend that needs to be analyzed across both the
technical and political complexities of cyberspace.
62
Conclusion
Unlike Internet fi ltering at the ISP level that is limited to local control, cyber attacks
conducted at strategically sensitive times have the ability to disrupt information fl ows
to international audiences right when the content may have the most impact. States
are obvious units of analysis when examining attribution and intent behind national
fi ltering regimes. However, actors and their intentions are not as readily apparent in
politically motivated cyber attacks. Despite the diffi culties, due to the political nature
of attacks against civil society organizations, many observers attribute these incidents
to government and military entities. As a result, the attackers ’ capabilities are often
overestimated, and their motivations are unknown. Although the issue of attribution
is essential to analysis of such attacks, it remains the most diffi cult and ambiguous
component of any investigation.
